Description
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Вредоносное расширение может перехватить контроль над ИИ-помощниками в Chromium-браузерахru-ru·Хакер (xakep.ru)· PoC Chrome web-app
- BragJack attacks hijack AI browser agents through malicious extensionsen-us·BleepingComputer· PoC Google Chrome ai-ml
- BragJack Attack Can Turn a Browser's Agentic AI Against Iten·Dark Reading· PoC Chrome ai-ml
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claudeen·The Hacker News· PoC Chrome ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-0628 and every CVE in our database. Create a free account — no credit card required.
Create Free Account